Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a link to the crates.io security page in SECURITY.md #6

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

carols10cents
Copy link
Member

Crates.io now has its own security page that has information relevant to the broader Rust ecosystem. People may look for this information in rust-lang's SECURITY.md. I think it makes sense to have that information linked here just in case.

Pietro is working on linking to https://crates.io/policies/security from https://www.rust-lang.org/policies/security, the latter of which is already linked here, but that's 2 clicks away.

I am open to wording changes to make this clearer; I am also open to this being rejected as not relevant in this location or not needed because the Rust security page will soon link to the crates.io security page.

But I'm on a mission to spread info that the Foundation can help crate authors with security problems by getting the information out as much as possible, so I figured I'd try adding it here and see what folks think.

Crates.io now has its own security page that has information relevant to the broader Rust ecosystem. People may look for this information in rust-lang/rust's SECURITY.md. I think it makes sense to have that information linked here just in case.
Copy link
Member

@Manishearth Manishearth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm in favor, speaking for myself. cc @pietroalbini @cuviper

@pietroalbini
Copy link
Member

Hmm, I'm not sure if this is the place for a link to the crates.io security policy to go. This would be shown in every repository's home page (example), and the link is not relevant for any repository except for maybe crates.io itself.

I'll try to prioritize getting the scope section merged into the security policy though, to hopefully alleviate the issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants